<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>cyberwart</title>
	<atom:link href="http://www.cyberwart.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cyberwart.com/blog</link>
	<description>Cyber Warfare Technologies</description>
	<pubDate>Sat, 06 Dec 2008 04:11:26 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>CYA Pen Test Style</title>
		<link>http://www.cyberwart.com/blog/2008/12/05/cya-pen-test-style/</link>
		<comments>http://www.cyberwart.com/blog/2008/12/05/cya-pen-test-style/#comments</comments>
		<pubDate>Sat, 06 Dec 2008 04:11:26 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
		
		<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=123</guid>
		<description><![CDATA[Today I was sort of surprised that basic CYA steps I use for pen testing weren&#8217;t immediately obvious to others. Maybe I&#8217;m exceptionally paranoid and worry to much but I thought I&#8217;d share some thoughts on the CYA business end of things.

Always start with a signed contract and rules of engagement. Do nothing without having [...]]]></description>
			<content:encoded><![CDATA[<p>Today I was sort of surprised that basic CYA steps I use for pen testing weren&#8217;t immediately obvious to others. Maybe I&#8217;m exceptionally paranoid and worry to much but I thought I&#8217;d share some thoughts on the CYA business end of things.</p>
<ol>
<li>Always start with a signed contract and rules of engagement. Do nothing without having this document.</li>
<li>Always read the Statement of Work (SoW) and the Rules of Engagement (RoE). These define both what you have to do and what you can&#8217;t do.</li>
<li>Always keep your PoC happy. Everything is much easier if your contact is happy. Make sure you ask them up front what they hope to get out of the engagement and check in to see that you&#8217;re meeting the objectives.</li>
<li>For any variation in the RoE/Contract feel it out verbally with the PoC first. If all is well, follow up with an email confirming what you heard and CC the project management. (good pen testers sometimes cheat, but this is how things should be done&#8230;)</li>
<li>Check with your management that your variations are cool. Sometimes actions are too risky for them and sometimes they don&#8217;t want to do free labor. This item really depends on your management.</li>
<li>If you put any tools or accounts on boxes notate it all in a spreadsheet as you do it. Track state, install, md5, uninstall &#8212; always uninstall/remove anything you create.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2008/12/05/cya-pen-test-style/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Computational Modeling</title>
		<link>http://www.cyberwart.com/blog/2008/12/05/computational-modeling/</link>
		<comments>http://www.cyberwart.com/blog/2008/12/05/computational-modeling/#comments</comments>
		<pubDate>Sat, 06 Dec 2008 03:56:57 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
		
		<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=119</guid>
		<description><![CDATA[For the most part, I&#8217;ve avoided general ranting on my blog. However tonight I feel compelled. First, hearing Amherst people rant about politics is hilarious. Foremost, being from DC I hear strong arguments about the difficulties of executing effective public policy. There are idealist, but their grounded in realities. For example, I&#8217;m hugely liberal and [...]]]></description>
			<content:encoded><![CDATA[<p>For the most part, I&#8217;ve avoided general ranting on my blog. However tonight I feel compelled. First, hearing Amherst people rant about politics is hilarious. Foremost, being from DC I hear strong arguments about the difficulties of executing effective public policy. There are idealist, but their grounded in realities. For example, I&#8217;m hugely liberal and I think issues such as homlessness should be fought. The difficulty is that as aid goes up, people are more inclined to rely on the safety net and the problem compounds. Here they seem to ignore such realities.</p>
<p>The thing that really suprises me is that they only theorize the systems. I&#8217;m probably overly inclined to build models and I&#8217;m fully aware of their flaws, but I can&#8217;t imagine a simulation would be worse of than pure brain power. Maybe I should go build one for the fun of it. I actually think it would be kind of interesting. I could roughly model a town or something with people, topology, income, political drive, etc. Add some randomness and see how things (d)evolve. Economic and political theory are amusing enough. I bet it could keep my attention long enough to build&#8230;now if only I didn&#8217;t have 10 other projects.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2008/12/05/computational-modeling/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Pen Testing on a Mac</title>
		<link>http://www.cyberwart.com/blog/2008/11/17/pen-testing-on-a-mac/</link>
		<comments>http://www.cyberwart.com/blog/2008/11/17/pen-testing-on-a-mac/#comments</comments>
		<pubDate>Tue, 18 Nov 2008 02:44:06 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
		
		<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=116</guid>
		<description><![CDATA[Adam talked me into buying a Macbook. It&#8217;s not overly hard to talk me into buying technology so lets not give him too much credit. Really, all I needed was a laptop that could do basic Internet type stuff and run VMware. As you may have read earlier, we were swamped with scanning so I [...]]]></description>
			<content:encoded><![CDATA[<p>Adam talked me into buying a Macbook. It&#8217;s not overly hard to talk me into buying technology so lets not give him too much credit. Really, all I needed was a laptop that could do basic Internet type stuff and run VMware. As you may have read earlier, we were swamped with scanning so I had to push two boxes to be scanning machines, which left me with limited ability to do real work or to stay up on business stuff like email.</p>
<p>So my experience so far: Everyone knows Macs are pretty. They&#8217;re light and have small sleek form factor. The display is lovely. They keyboard is spacious and easy to use. The touchpad took a bit to get use to, but overall I&#8217;m not happy with it. It&#8217;s multi-touch capable and overall a nifty tool once you learn how to use it.</p>
<p>Software is actually good. Vmware Fusion is nicer and more responsive than either VMware Workstation or Server. Graphics run far faster and it&#8217;s a nicer experience. Additionally, you can use &#8220;Unity&#8221; and run Windows software on the Mac desktop. The only thing that really irks me is that there isn&#8217;t a Vmware-server-console or a Firefox/Safari plugin to access VMware server easily. So access is through a contrived VM in a VM type thing or over X11. It&#8217;s ugly, but it&#8217;s been fairly successful.</p>
<p>Port is my friend. It installs basically everything you might want. It has some quirks, but being a Gentoo guy I&#8217;m use to a certain amount of pain when moving to a new OS. Port builds from source and usually works &#8212; once you learn a few tricks. I have Wireshark, libpcap, libnet, scapy, python, CANVAS, metasploit, kismet, nmap, and hping working. Nessus has an install for Mac.</p>
<p>My Verizon Mobile Card works fine</p>
<p>MS Office is fine. It looks a little different but it&#8217;s Office.</p>
<p>Hardware is blazing. I have 4 gigs of Ram. A 250 gb hard drive and a 2.4Ghz Core duo.</p>
<p>Overall, I think it&#8217;s a very positive experience and I&#8217;d recommend it if you have a bit of tim to invest in getting familiar with the OS and getting the tools that you need onto the box.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2008/11/17/pen-testing-on-a-mac/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Long Live Non-MS Bugs</title>
		<link>http://www.cyberwart.com/blog/2008/11/16/long-live-non-ms-bugs/</link>
		<comments>http://www.cyberwart.com/blog/2008/11/16/long-live-non-ms-bugs/#comments</comments>
		<pubDate>Sun, 16 Nov 2008 20:26:16 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
		
		<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=114</guid>
		<description><![CDATA[Everyone loves to beat up on Microsoft. Hell, I do&#8230; sorry Carric. But Microsoft is slowly getting it&#8217;s software in order and organizations are learning to patch it very quickly. Personally,  love doing exploit development on small custom software. But in a recent case, I saw a larger software package with a known bug but [...]]]></description>
			<content:encoded><![CDATA[<p>Everyone loves to beat up on Microsoft. Hell, I do&#8230; sorry Carric. But Microsoft is slowly getting it&#8217;s software in order and organizations are learning to patch it very quickly. Personally,  love doing exploit development on small custom software. But in a recent case, I saw a larger software package with a known bug but no exploit.</p>
<p>In particular, I&#8217;m talking about the command execution vuln released in October for BrightStor ARCServe. BID 31684.</p>
<p>To actually exploit the bug use Nessus/Nasl</p>
<p>Find the file: arcserve_command_exec.nasl</p>
<p>Copy it somewhere and edit. Change the following:</p>
<ol>
<li>Ditch the requirements. Comment out<br />
#script_require_keys(&#8221;Host/OS/smb&#8221;)<br />
#script_require_ports (6504);</li>
<li>Manually set the hostname<br />
host = kb_smb_name(); to host = &#8220;hostname&#8221;; Note, and IP won&#8217;t work</li>
<li>Change the cmd<br />
cmd = &#8220;ifconfig&#8221;; to whatever you want</li>
<li>Change the output to use the display() function so you can see what happens</li>
<li>Run the NASL<br />
nasl -t target_ip_or_hostname yournasl.nasl</li>
</ol>
<p>Yes, this is a bit clunky, but it&#8217;s a fairly quick way to execute arbitrary commands on the remote system. RPC (IMO) is difficult and I&#8217;d rather not deal with it if some else already has.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2008/11/16/long-live-non-ms-bugs/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The Sorry State of Vuln Scanners</title>
		<link>http://www.cyberwart.com/blog/2008/11/16/the-sorry-state-of-vuln-scanners/</link>
		<comments>http://www.cyberwart.com/blog/2008/11/16/the-sorry-state-of-vuln-scanners/#comments</comments>
		<pubDate>Sun, 16 Nov 2008 20:16:26 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
		
		<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=112</guid>
		<description><![CDATA[I&#8217;ve decided that I truly HATE most vulnerability scanners. Generally I don&#8217;t trust the things, but they&#8217;ve always done a fair job of giving me a checkbox for patches and by providing a little guidance on how to attack a network. Well recently we&#8217;re had to scan multiple class B networks both internally and externally. [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve decided that I truly HATE most vulnerability scanners. Generally I don&#8217;t trust the things, but they&#8217;ve always done a fair job of giving me a checkbox for patches and by providing a little guidance on how to attack a network. Well recently we&#8217;re had to scan multiple class B networks both internally and externally. It&#8217;s been brutal. Nothing finishes, results vary. It sucks hardcore.</p>
<p>I&#8217;ve noticed a few things. First, it&#8217;s almost impossible to by vuln scanning software these days. Everyone wants to sell an appliance .As a consultant that doesn&#8217;t really work for me. I need to take the software with me on a laptop into a client site. An appliance makes the software basically useless.</p>
<p>So our Qualys box is out of the mix. Next we moved onto Nessus. Who doesn&#8217;t love Nessus? It&#8217;s not flashy but it gets the job done&#8230; right? Well no. It crashed. Over and over. It wouldn&#8217;t save state and if it crashed you had to restart.</p>
<p>Fuck.</p>
<p>Sure you say, do small bunches at once. Well this shouldn&#8217;t matter. It irked me that Nessus didn&#8217;t do the host management/scanning properly itself. Manually manging it is nuts. But worse, If you break scans into small bunches, you then have to merge all the results at the end.</p>
<p>Next I tried an old FS image. Well that can pause scans and resume them after a crash, but it&#8217;s had previous known issues. Further, it won&#8217;t finish. It&#8217;s hung at 99% done for days. I&#8217;ve checked and it&#8217;s still running scans and producing results but 99% for days.</p>
<p>I find it sad that a team of pen testers, some previously software developers, and all experienced with the tools can&#8217;t get them to work effectively.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2008/11/16/the-sorry-state-of-vuln-scanners/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Kiosk Fun</title>
		<link>http://www.cyberwart.com/blog/2008/11/16/kiosk-fun/</link>
		<comments>http://www.cyberwart.com/blog/2008/11/16/kiosk-fun/#comments</comments>
		<pubDate>Sun, 16 Nov 2008 20:06:05 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
		
		<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=104</guid>
		<description><![CDATA[As most of my friends know, I have a tendency to run late. Well I was running late the other day holding up my friend, Adam Pridgen. He was patiently waiting for me in the hotel lobby and started playing with the kiosk. I beleive the particular software is kiosksafe. I had ran into it [...]]]></description>
			<content:encoded><![CDATA[<p>As most of my friends know, I have a tendency to run late. Well I was running late the other day holding up my friend,<a href="http://www.thecoverofnight.com" target="_blank"> Adam Pridgen</a>. He was patiently waiting for me in the hotel lobby and started playing with the kiosk. I beleive the particular software is kiosksafe. I had ran into it before and knew that it did a fair job. The software not only remaps/intercepts kep strokes but it also appears to run some sort of rootkit. When a particular API is called &#8212; or possibly a window has a certain name, the software locks the site down. It&#8217;s most unfortunate.</p>
<p>I threw <a href="http://ikat.ha.cked.net/" target="_blank">iKat</a> at it for fun. I saw iKat at defcon and always wanted to give it a try. It did a fair job of crashing the hell out of the Kiosk but it gave me fairly limited results.</p>
<p>Everyone knows the typical file-menu type hacks trying to find something that opens up  the system in a somewhat clever manner. Those didn&#8217;t work, but Office had potential. So I decided to play. In the end, I got a fair amount of access with a Word doc. <img src='http://www.cyberwart.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>First, change the default configuration paths for Word. This just makes sure Word opens up with high level access. I generally set it to C:\</p>
<p>The below screenshots show most of the process</p>
<p><a href="http://www.cyberwart.com/blog/wp-content/uploads/2008/11/11-14-2008-4-46-21-pm.png"><img class="alignnone size-medium wp-image-105" title="11-14-2008-4-46-21-pm" src="http://www.cyberwart.com/blog/wp-content/uploads/2008/11/11-14-2008-4-46-21-pm-600x489.png" alt="" width="600" height="489" /></a></p>
<p><a href="http://www.cyberwart.com/blog/wp-content/uploads/2008/11/11-14-2008-4-51-21-pm.png"><img class="alignnone size-medium wp-image-106" title="11-14-2008-4-51-21-pm" src="http://www.cyberwart.com/blog/wp-content/uploads/2008/11/11-14-2008-4-51-21-pm-600x84.png" alt="" width="600" height="84" /></a></p>
<p><a href="http://www.cyberwart.com/blog/wp-content/uploads/2008/11/11-14-2008-4-52-21-pm.png"><img class="alignnone size-medium wp-image-107" title="11-14-2008-4-52-21-pm" src="http://www.cyberwart.com/blog/wp-content/uploads/2008/11/11-14-2008-4-52-21-pm.png" alt="" width="508" height="345" /></a></p>
<p><a href="http://www.cyberwart.com/blog/wp-content/uploads/2008/11/11-14-2008-4-53-48-pm.png"><img class="alignnone size-medium wp-image-108" title="11-14-2008-4-53-48-pm" src="http://www.cyberwart.com/blog/wp-content/uploads/2008/11/11-14-2008-4-53-48-pm-600x375.png" alt="" width="600" height="375" /></a></p>
<p><a href="http://www.cyberwart.com/blog/wp-content/uploads/2008/11/11-14-2008-4-54-30-pm.png"><img class="alignnone size-medium wp-image-109" title="11-14-2008-4-54-30-pm" src="http://www.cyberwart.com/blog/wp-content/uploads/2008/11/11-14-2008-4-54-30-pm-600x376.png" alt="" width="600" height="376" /></a></p>
<p>Double click the icon and hopefully it works for you. cmd.exe sometimes has issues but IE, Windows Media Player, etc work a little better</p>
<p>Sample word doc provided shortly.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2008/11/16/kiosk-fun/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Teaching at a University</title>
		<link>http://www.cyberwart.com/blog/2008/11/16/teaching-at-a-university/</link>
		<comments>http://www.cyberwart.com/blog/2008/11/16/teaching-at-a-university/#comments</comments>
		<pubDate>Sun, 16 Nov 2008 19:48:24 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
		
		<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=102</guid>
		<description><![CDATA[I had the opportunity to teach class at a University last week. It was an interesting experience. A friend of mine, Adam Pridgen, co lectured with me. The class was a senior level seminar type class on computer security. I wasn’t sure exactly what to expect going into the class, but I had done a [...]]]></description>
			<content:encoded><![CDATA[<p>I had the opportunity to teach class at a University last week. It was an interesting experience. A friend of mine, <a href="http://www.thecoverofnight.com" target="_blank">Adam Pridgen</a>, co lectured with me. The class was a senior level seminar type class on computer security. I wasn’t sure exactly what to expect going into the class, but I had done a previous intro to penetration testing so I updated that and went in.<br />
The class started with an intro presentation by one of the students. It appears the students update the class with a somewhat recent security topic. In this case, it was a 5 minute overview of the uTorrent overflow. I was immediately nervous as I only had 10-15% of my slides at the in-depth exploitation/fuzzing level. I was worried that I would bore the class or not be able to speak with enough knowledge of particular exploits straight from memory. After the student got past the first slide or two, there were some contradictions and inaccuracies. The students didn’t jump on it so I figured I wasn’t in too much trouble.</p>
<p>Shortly there after, Adam and I were introduced and we went into our thing. We talked about some of the common mistakes that really enable attackers to compromise networks. We discussed some of the tools and techniques we used – giving examples of situations where we had used them. Unfortunately, I don’t think they really connected. The professor got into it, but not the students. Between a couple non-public bugs/attacks and the story of the power company CEO ignoring the out-briefing until I showed a screenshot of his email – I thought we were golden. But I guess such is the state of computer security education right now.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2008/11/16/teaching-at-a-university/feed/</wfw:commentRss>
		</item>
		<item>
		<title>MS08-067 Update</title>
		<link>http://www.cyberwart.com/blog/2008/10/23/ms08-067-update/</link>
		<comments>http://www.cyberwart.com/blog/2008/10/23/ms08-067-update/#comments</comments>
		<pubDate>Thu, 23 Oct 2008 18:36:15 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
		
		<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=97</guid>
		<description><![CDATA[From MS:
Published: October 14, 2008 &#124; Updated: October 23, 2008
Version: 3.0
This bulletin summary lists security bulletins released for October 2008.
With the release of the bulletins for October 2008, this bulletin summary replaces the bulletin advance notification originally issued October 9, 2008. For more information about the bulletin advance notification service, see Microsoft Security Bulletin Advance [...]]]></description>
			<content:encoded><![CDATA[<p>From MS:</p>
<div class="date">Published: October 14, 2008<span class="datePipe"> | </span>Updated: October 23, 2008</div>
<p><strong>Version:</strong> 3.0</p>
<p>This bulletin summary lists security bulletins released for October 2008.</p>
<p>With the release of the bulletins for October 2008, this bulletin summary replaces the bulletin advance notification originally issued October 9, 2008. For more information about the bulletin advance notification service, see <a href="http://www.microsoft.com/technet/security/Bulletin/advance.mspx">Microsoft Security Bulletin Advance Notification</a>.</p>
<p>For information about how to receive automatic notifications whenever Microsoft security bulletins are issued, visit <a href="http://go.microsoft.com/fwlink/?LinkId=21163">Microsoft Technical Security Notifications</a>.</p>
<p>Microsoft is hosting a webcast to address customer questions on these bulletins on October 15, 2008, at 11:00 AM Pacific Time (US &amp; Canada). <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032374639">Register now for the October Security Bulletin Webcast</a>. After this date, this webcast is available on-demand. For more information, see <a href="http://www.microsoft.com/technet/security/bulletin/summary.mspx">Microsoft Security Bulletin Summaries and Webcasts</a>.</p>
<p>For the out-of-band security bulletin added to Version 3.0 of this bulletin summary, Microsoft is hosting a webcast to address customer questions on October 23, 2008, at 1:00 PM Pacific Time (US &amp; Canada). <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032393978&amp;EventCategory=4&amp;culture=en-US&amp;CountryCode=US">Register now for the Out-of-Band Security Bulletin Webcast</a>. After this date, this webcast is available on-demand. For more information, see <a href="http://www.microsoft.com/technet/security/bulletin/summary.mspx">Microsoft Security Bulletin Summaries and Webcasts</a>.</p>
<p>Microsoft also provides information to help customers prioritize monthly security updates with any non-security, high-priority updates that are being released on the same day as the monthly security updates. Please see the section, <strong>Other Information</strong>.</p>
<h2 class="extra">Bulletin Information</h2>
<div class="expandoIndent" style="margin-bottom: 15px;"><a name="EUC"></a><script type="text/javascript"><!--
sID='8l1-EUC'
// --></script></p>
<h3>Executive Summaries</h3>
<div id="s8l1-EUC">
<p>The security bulletins for this month are as follows, in order of severity:</p>
<p><a name="EXC"></a></p>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding: 2px 6px 0px 0px;"><script type="text/javascript"><!--
sID='8l2-EXC';writePM(sID)
// --></script><a href="javascript:Toggle('s8l2-EXC')"><img id="is8l2-EXC" src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/plus.gif" border="0" alt="" width="9" height="9" /></a></td>
<td class="secLabel"><script type="text/javascript"><!--
startA('s'+sID)
// --></script></p>
<h4><a style="text-decoration: none;" href="javascript:Toggle('s8l2-EXC')">Critical (5)</a></h4>
<p><script type="text/javascript"><!--
endA()
// --></script></td>
</tr>
</tbody>
</table>
<div id="s8l2-EXC" style="display: none;"><script type="text/javascript"><!--
chkHide('s'+sID);
// --></script></p>
<div class="expandoIndent">
<table id="E2C" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="81%">
<thead>
<tr class="stdHeader" valign="top">
<td id="colE5C" width="24%">Bulletin Identifier</td>
<td id="colECD" style="border-right: 1px solid #cccccc;" width="75%">Microsoft Security Bulletin MS08-067</td>
</tr>
</thead>
<tbody>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Title</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=130719"><strong>Vulnerability in Server Service Could Allow Remote Code Execution (958644)</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Executive Summary</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">This security update resolves a privately reported vulnerability in the Server service. The vulnerability could allow remote code execution if an affected system received a specially crafted RPC request. On Microsoft Windows 2000, Windows XP, and Windows Server 2003 systems, an attacker could exploit this vulnerability without authentication to run arbitrary code. It is possible that this vulnerability could be used in the crafting of a wormable exploit. Firewall best practices and standard default firewall configurations can help protect network resources from attacks that originate outside the enterprise perimeter.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Maximum Severity Rating</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Impact of Vulnerability</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Remote Code Execution</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Detection</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update requires a restart.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Affected Software</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><strong>Microsoft Windows.</strong> For more information, see the Affected Software and Download Locations section.</p>
</td>
</tr>
</tbody>
</table>
<table id="E4E" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="81%">
<thead>
<tr class="stdHeader" valign="top">
<td id="colEAF" width="24%">Bulletin Identifier</td>
<td id="colEEF" style="border-right: 1px solid #cccccc;" width="75%">Microsoft Security Bulletin MS08-060</td>
</tr>
</thead>
<tbody>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Title</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128125"><strong>Vulnerability in Active Directory Could Allow Remote Code Execution (957280)</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Executive Summary</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">This security update resolves a privately reported vulnerability in implementations of Active Directory on Microsoft Windows 2000 Server. The vulnerability could allow remote code execution if an attacker gains access to an affected network. This vulnerability only affects Microsoft Windows 2000 servers configured to be domain controllers. If a Microsoft Windows 2000 server has not been promoted to a domain controller, it will not be listening to Lightweight Directory Access Protocol (LDAP) or LDAP over SSL (LDAPS) queries, and will not be exposed to this vulnerability.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Maximum Severity Rating</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Impact of Vulnerability</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Remote Code Execution</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Detection</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update requires a restart.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Affected Software</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><strong>Microsoft Windows.</strong> For more information, see the Affected Software and Download Locations section.</p>
</td>
</tr>
</tbody>
</table>
<table id="E6G" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="81%">
<thead>
<tr class="stdHeader" valign="top">
<td id="colECH" width="24%">Bulletin Identifier</td>
<td id="colEGH" style="border-right: 1px solid #cccccc;" width="75%">Microsoft Security Bulletin MS08-058</td>
</tr>
</thead>
<tbody>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Title</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=128060"><strong>Cumulative Security Update for Internet Explorer (956390)</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Executive Summary</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">This security update resolves five privately reported vulnerabilities and one publicly disclosed vulnerability. The vulnerabilities could allow information disclosure or remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Maximum Severity Rating</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Impact of Vulnerability</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Remote Code Execution</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Detection</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update requires a restart.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Affected Software</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><strong>Microsoft Windows, Internet Explorer.</strong> For more information, see the Affected Software and Download Locations section.</p>
</td>
</tr>
</tbody>
</table>
<table id="ECBAC" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="81%">
<thead>
<tr class="stdHeader" valign="top">
<td id="colEFBAC" width="24%">Bulletin Identifier</td>
<td id="colEJBAC" style="border-right: 1px solid #cccccc;" width="75%">Microsoft Security Bulletin MS08-059</td>
</tr>
</thead>
<tbody>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Title</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=125712"><strong>Vulnerability in Host Integration Server RPC Service Could Allow Remote Code Execution (956695)</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Executive Summary</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">This security update resolves a privately reported vulnerability in Microsoft Host Integration Server. The vulnerability could allow remote code execution if an attacker sent a specially crafted Remote Procedure Call (RPC) request to an affected system. Customers who follow best practices and configure the SNA RPC service account to have fewer user rights on the system could be less impacted than customers who configure the SNA RPC service account to have administrative user rights.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Maximum Severity Rating</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Impact of Vulnerability</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Remote Code Execution</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Detection</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update may require a restart.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Affected Software</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><strong>Microsoft Host Integration Server.</strong> For more information, see the Affected Software and Download Locations section.</p>
</td>
</tr>
</tbody>
</table>
<table id="EEDAC" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="81%">
<thead>
<tr class="stdHeader" valign="top">
<td id="colEHDAC" width="24%">Bulletin Identifier</td>
<td id="colELDAC" style="border-right: 1px solid #cccccc;" width="75%">Microsoft Security Bulletin MS08-057</td>
</tr>
</thead>
<tbody>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Title</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=124653"><strong>Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Executive Summary</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">This security update resolves three privately reported vulnerabilities in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Maximum Severity Rating</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Impact of Vulnerability</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Remote Code Execution</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Detection</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update does not require a restart.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Affected Software</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><strong>Microsoft Office.</strong> For more information, see the Affected Software and Download Locations section.</p>
</td>
</tr>
</tbody>
</table>
</div>
<div class="secTop"><a href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EXC"><img src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/arrow_px_up.gif" border="0" alt="Top of section" width="7" height="9" /></a><a class="topOfPage" href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EXC">Top of section</a></div>
</div>
<p><a name="EFFAC"></a></p>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding: 2px 6px 0px 0px;"><script type="text/javascript"><!--
sID='8l2-EFFAC';writePM(sID)
// --></script><a href="javascript:Toggle('s8l2-EFFAC')"><img id="is8l2-EFFAC" src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/plus.gif" border="0" alt="" width="9" height="9" /></a></td>
<td class="secLabel"><script type="text/javascript"><!--
startA('s'+sID)
// --></script></p>
<h4><a style="text-decoration: none;" href="javascript:Toggle('s8l2-EFFAC')">Important (6)</a></h4>
<p><script type="text/javascript"><!--
endA()
// --></script></td>
</tr>
</tbody>
</table>
<div id="s8l2-EFFAC" style="display: none;"><script type="text/javascript"><!--
chkHide('s'+sID);
// --></script></p>
<div class="expandoIndent">
<table id="EJFAC" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="81%">
<thead>
<tr class="stdHeader" valign="top">
<td id="colEMFAC" width="24%">Bulletin Identifier</td>
<td id="colEQFAC" style="border-right: 1px solid #cccccc;" width="75%">Microsoft Security Bulletin MS08-066</td>
</tr>
</thead>
<tbody>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Title</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=125709"><strong>Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (956803)</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Executive Summary</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">This security update resolves a privately reported vulnerability in the Microsoft Ancillary Function Driver. A local attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Maximum Severity Rating</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Impact of Vulnerability</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Elevation of Privilege</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Detection</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update requires a restart.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Affected Software</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><strong>Microsoft Windows.</strong> For more information, see the Affected Software and Download Locations section.</p>
</td>
</tr>
</tbody>
</table>
<table id="ELHAC" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="81%">
<thead>
<tr class="stdHeader" valign="top">
<td id="colEOHAC" width="24%">Bulletin Identifier</td>
<td id="colESHAC" style="border-right: 1px solid #cccccc;" width="75%">Microsoft Security Bulletin MS08-061</td>
</tr>
</thead>
<tbody>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Title</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=121738"><strong>Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Executive Summary</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">This security update resolves one publicly disclosed and two privately reported vulnerabilities in the Windows kernel. A local attacker who successfully exploited these vulnerabilities could take complete control of an affected system. The vulnerabilities could not be exploited remotely or by anonymous users.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Maximum Severity Rating</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Impact of Vulnerability</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Elevation of Privilege</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Detection</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update requires a restart.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Affected Software</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><strong>Microsoft Windows.</strong> For more information, see the Affected Software and Download Locations section.</p>
</td>
</tr>
</tbody>
</table>
<table id="ENJAC" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="81%">
<thead>
<tr class="stdHeader" valign="top">
<td id="colEQJAC" width="24%">Bulletin Identifier</td>
<td id="colEUJAC" style="border-right: 1px solid #cccccc;" width="75%">Microsoft Security Bulletin MS08-062</td>
</tr>
</thead>
<tbody>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Title</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=120829"><strong>Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (953155)</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Executive Summary</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">This update resolves a privately reported vulnerability in the Windows Internet Printing Service that could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Maximum Severity Rating</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Impact of Vulnerability</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Remote Code Execution</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Detection</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update requires a restart.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Affected Software</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><strong>Microsoft Windows.</strong> For more information, see the Affected Software and Download Locations section.</p>
</td>
</tr>
</tbody>
</table>
<table id="EPLAC" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="81%">
<thead>
<tr class="stdHeader" valign="top">
<td id="colESLAC" width="24%">Bulletin Identifier</td>
<td id="colEWLAC" style="border-right: 1px solid #cccccc;" width="75%">Microsoft Security Bulletin MS08-063</td>
</tr>
</thead>
<tbody>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Title</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=127994"><strong>Vulnerability in SMB Could Allow Remote Code Execution (957095)</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Executive Summary</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">This security update resolves a privately reported vulnerability in Microsoft Server Message Block (SMB) Protocol. The vulnerability could allow remote code execution on a server that is sharing files or folders. An attacker who successfully exploited these vulnerabilities could install programs; view, change, or delete data; or create new accounts with full user rights.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Maximum Severity Rating</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Impact of Vulnerability</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Remote Code Execution</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Detection</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update requires a restart.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Affected Software</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><strong>Microsoft Windows.</strong> For more information, see the Affected Software and Download Locations section.</p>
</td>
</tr>
</tbody>
</table>
<table id="ERNAC" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="81%">
<thead>
<tr class="stdHeader" valign="top">
<td id="colEUNAC" width="24%">Bulletin Identifier</td>
<td id="colEYNAC" style="border-right: 1px solid #cccccc;" width="75%">Microsoft Security Bulletin MS08-064</td>
</tr>
</thead>
<tbody>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Title</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128103"><strong>Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (956841)</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Executive Summary</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">This security update resolves a privately reported vulnerability in Virtual Address Descriptor. The vulnerability could allow elevation of privilege if a user runs a specially crafted application. An authenticated attacker who successfully exploited this vulnerability could gain elevation of privilege on an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Maximum Severity Rating</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Impact of Vulnerability</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Elevation of Privilege</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Detection</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update requires a restart.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Affected Software</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><strong>Microsoft Windows.</strong> For more information, see the Affected Software and Download Locations section.</p>
</td>
</tr>
</tbody>
</table>
<table id="ETPAC" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="81%">
<thead>
<tr class="stdHeader" valign="top">
<td id="colEWPAC" width="24%">Bulletin Identifier</td>
<td id="colE1PAC" style="border-right: 1px solid #cccccc;" width="75%">Microsoft Security Bulletin MS08-065</td>
</tr>
</thead>
<tbody>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Title</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128102"><strong>Vulnerability in Message Queuing Could Allow Remote Code Execution (951071)</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Executive Summary</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">This security update resolves a privately reported vulnerability in the Message Queuing Service (MSMQ) on Microsoft Windows 2000 systems. The vulnerability could allow remote code execution on Microsoft Windows 2000 systems with the MSMQ service enabled.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Maximum Severity Rating</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Impact of Vulnerability</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Remote Code Execution</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Detection</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update requires a restart.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Affected Software</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><strong>Microsoft Windows.</strong> For more information, see the Affected Software and Download Locations section.</p>
</td>
</tr>
</tbody>
</table>
</div>
<div class="secTop"><a href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EFFAC"><img src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/arrow_px_up.gif" border="0" alt="Top of section" width="7" height="9" /></a><a class="topOfPage" href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EFFAC">Top of section</a></div>
</div>
<p><a name="EVBAE"></a></p>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding: 2px 6px 0px 0px;"><script type="text/javascript"><!--
sID='8l2-EVBAE';writePM(sID)
// --></script><a href="javascript:Toggle('s8l2-EVBAE')"><img id="is8l2-EVBAE" src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/plus.gif" border="0" alt="" width="9" height="9" /></a></td>
<td class="secLabel"><script type="text/javascript"><!--
startA('s'+sID)
// --></script></p>
<h4><a style="text-decoration: none;" href="javascript:Toggle('s8l2-EVBAE')">Moderate (1)</a></h4>
<p><script type="text/javascript"><!--
endA()
// --></script></td>
</tr>
</tbody>
</table>
<div id="s8l2-EVBAE" style="display: none;"><script type="text/javascript"><!--
chkHide('s'+sID);
// --></script></p>
<div class="expandoIndent">
<table id="EZBAE" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="81%">
<thead>
<tr class="stdHeader" valign="top">
<td id="colE3BAE" width="24%">Bulletin Identifier</td>
<td id="colEACAE" style="border-right: 1px solid #cccccc;" width="75%">Microsoft Security Bulletin MS08-056</td>
</tr>
</thead>
<tbody>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Title</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128145"><strong>Vulnerability in Microsoft Office Could Allow Information Disclosure (957699)</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Executive Summary</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow information disclosure if a user clicks a specially crafted CDO URL. An attacker who successfully exploited this vulnerability could inject a client-side script in the user&#8217;s browser that could spoof content, disclose information, or take any action that the user could take on the affected Web site.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Maximum Severity Rating</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Moderate</a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Impact of Vulnerability</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Information Disclosure</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Detection</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update does not require a restart.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Affected Software</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><strong>Microsoft Office.</strong> For more information, see the Affected Software and Download Locations section.</p>
</td>
</tr>
</tbody>
</table>
</div>
<div class="secTop"><a href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EVBAE"><img src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/arrow_px_up.gif" border="0" alt="Top of section" width="7" height="9" /></a><a class="topOfPage" href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EVBAE">Top of section</a></div>
</div>
<div class="secTop"><a href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EUC"><img src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/arrow_px_up.gif" border="0" alt="Top of section" width="7" height="9" /></a><a class="topOfPage" href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EUC">Top of section</a></div>
</div>
<p><a name="E1DAE"></a></p>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding: 6px 6px 0px 0px;"><script type="text/javascript"><!--
sID='8l1-E1DAE';writePM(sID)
// --></script><a href="javascript:Toggle('s8l1-E1DAE')"><img id="is8l1-E1DAE" src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/plus.gif" border="0" alt="" width="9" height="9" /></a></td>
<td class="secLabel"><script type="text/javascript"><!--
startA('s'+sID)
// --></script></p>
<h3><a style="text-decoration: none;" href="javascript:Toggle('s8l1-E1DAE')">Exploitability Index</a></h3>
<p><script type="text/javascript"><!--
endA()
// --></script></td>
</tr>
</tbody>
</table>
<div id="s8l1-E1DAE" style="display: none;"><script type="text/javascript"><!--
chkHide('s'+sID);
// --></script></p>
<div class="expandoIndent">
<p><strong>How do I use this table?</strong></p>
<p>Use this table to learn about the likelihood of functioning exploit code to be released for each of the security updates that you may need to install. You should review each of the assessments below, in accordance with your specific configuration, in order to prioritize your deployment. For more information about what these ratings mean, and how they are determined, please see <a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">Microsoft Exploit Index</a>.</p>
<table id="EGEAE" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="85%">
<thead>
<tr class="stdHeader" valign="top">
<td id="colEJEAE" width="14%">Bulletin ID</td>
<td id="colENEAE" width="23%">Bulletin Title</td>
<td id="colEREAE" width="15%">CVE ID</td>
<td id="colEVEAE" width="13%">Exploitability Index Assessment</td>
<td id="colEZEAE" style="border-right: 1px solid #cccccc;" width="33%">Key Notes</td>
</tr>
</thead>
<tbody>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128145">MS08-056</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128145">Vulnerability in Microsoft Office Could Allow Information Disclosure (957699)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-4020</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">2 - Inconsistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Functioning exploit code could be created. However, the severity impact is limited as the vulnerability allows spoofing in a dialog in specific Web application scenarios only. As a result, this may get little attention from attackers.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=124653">MS08-057</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=124653">Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-4019</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">1 - Consistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=124653">MS08-057</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=124653">Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-3471</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">2 - Inconsistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=124653">MS08-057</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=124653">Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-3477</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">2 - Inconsistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128060">MS08-058</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=128060">Cumulative Security Update for Internet Explorer (956390)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-2947</p>
</td>
<td>
<p class="lastInCell">(Public at bulletin release)</p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128060">MS08-058</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=128060">Cumulative Security Update for Internet Explorer (956390)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-3472</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">1 - Consistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128060">MS08-058</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=128060">Cumulative Security Update for Internet Explorer (956390)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-3473</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">1 - Consistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128060">MS08-058</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=128060">Cumulative Security Update for Internet Explorer (956390)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-3475</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">2 - Inconsistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128060">MS08-058</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=128060">Cumulative Security Update for Internet Explorer (956390)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-3474</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">3 - Functioning exploit code unlikely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128060">MS08-058</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=128060">Cumulative Security Update for Internet Explorer (956390)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-3476</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">3 - Functioning exploit code unlikely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=125712">MS08-059</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=125712">Vulnerability in Host Integration Server RPC Service Could Allow Remote Code Execution (956695)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-3466</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">1 - Consistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">While only specific types of enterprise customers would likely install Host Integration Server, functioning exploit code is likely to be created.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128125">MS08-060</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128125">Vulnerability in Active Directory Could Allow Remote Code Execution (957280)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-4023</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">2 - Inconsistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Triggering the vulnerability to cause a denial of service condition is likely. However, creating functioning exploit code to leverage remote code execution is difficult due to not being able to control a needed write address.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=121738">MS08-061</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=121738">Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-2250</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">1 - Consistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=121738">MS08-061</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=121738">Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-2252</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">1 - Consistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Functioning exploit is most likely to be created for multiprocessor systems.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=121738">MS08-061</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=121738">Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-2251</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">3 - Functioning exploit code unlikely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Triggering the vulnerability may be possible, but successful, functioning exploit code is very difficult to create.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=120829">MS08-062</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=120829">Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (953155)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-1446</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">1 - Consistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Consistent exploit code has been discovered in limited, targeted attacks. While the Internet Printing Protocol (IPP) service is enabled by default, access to this service using IIS also requires authentication by default on all platforms.</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=127994">MS08-063</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=127994">Vulnerability in SMB Could Allow Remote Code Execution (957095)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-4038</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">2 - Inconsistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128103">MS08-064</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128103">Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (956841)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-4036</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">2 - Inconsistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128102">MS08-065</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128102">Vulnerability in Message Queuing Could Allow Remote Code Execution (951071)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-3479</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">3 - Functioning exploit code unlikely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">While information disclosure might be possible, obtaining useful content from memory is not always possible. The memory corruption issue can be triggered, but remote code execution is difficult to gain.</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=125709">MS08-066</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=125709">Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (956803)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-3464</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">1 - Consistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=130719">MS08-067</a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=130719">Vulnerability in Server Service Could Allow Remote Code Execution (958644)</a></p>
</td>
<td>
<p class="lastInCell">CVE-2008-4250</p>
</td>
<td>
<p class="lastInCell"><a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">1 - Consistent exploit code likely</a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Consistent exploit code has been discovered in limited, targeted attacks, affecting Windows XP and Windows Server 2003. While this service is enabled by default on all affected platforms, exploitation is most likely on Microsoft Windows 2000, Windows XP, and Windows Server 2003. Default installations of Windows Vista and Windows Server 2008 require authentication due to protections introduced as part of UAC that enforce additional levels of integrity. This protection is in place even if the UAC prompt is disabled. Even after authentication, ASLR and DEP enhancements will present obstacles to exploitation.</p>
</td>
</tr>
</tbody>
</table>
</div>
<div class="secTop"><a href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#E1DAE"><img src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/arrow_px_up.gif" border="0" alt="Top of section" width="7" height="9" /></a><a class="topOfPage" href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#E1DAE">Top of section</a></div>
</div>
<p><a name="E6RAE"></a></p>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding: 6px 6px 0px 0px;"><script type="text/javascript"><!--
sID='8l1-E6RAE';writePM(sID)
// --></script><a href="javascript:Toggle('s8l1-E6RAE')"><img id="is8l1-E6RAE" src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/plus.gif" border="0" alt="" width="9" height="9" /></a></td>
<td class="secLabel"><script type="text/javascript"><!--
startA('s'+sID)
// --></script></p>
<h3><a style="text-decoration: none;" href="javascript:Toggle('s8l1-E6RAE')">Affected Software and Download Locations</a></h3>
<p><script type="text/javascript"><!--
endA()
// --></script></td>
</tr>
</tbody>
</table>
<div id="s8l1-E6RAE" style="display: none;"><script type="text/javascript"><!--
chkHide('s'+sID);
// --></script></p>
<div class="expandoIndent">
<p><strong>How do I use this table?</strong></p>
<p>Use this table to learn about the security updates that you may need to install. You should review each software program or component listed to see whether any security updates are required. If a software program or component is listed, then the available software update is hyperlinked and the severity rating of the software update is also listed.</p>
<p><strong>Note</strong> You may have to install several security updates for a single vulnerability. Review the whole column for each bulletin identifier that is listed to verify the updates that you have to install, based on the programs or components that you have installed on your system.</p>
<p><a name="EKSAE"></a></p>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding: 2px 6px 0px 0px;"><script type="text/javascript"><!--
sID='8l2-EKSAE';writePM(sID)
// --></script><a href="javascript:Toggle('s8l2-EKSAE')"><img id="is8l2-EKSAE" src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/plus.gif" border="0" alt="" width="9" height="9" /></a></td>
<td class="secLabel"><script type="text/javascript"><!--
startA('s'+sID)
// --></script></p>
<h4><a style="text-decoration: none;" href="javascript:Toggle('s8l2-EKSAE')">Windows Operating System and Components</a></h4>
<p><script type="text/javascript"><!--
endA()
// --></script></td>
</tr>
</tbody>
</table>
<div id="s8l2-EKSAE" style="display: none;"><script type="text/javascript"><!--
chkHide('s'+sID);
// --></script></p>
<div class="expandoIndent">
<table id="EOSAE" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="83%">
<thead></thead>
<tbody>
<tr class="subHeader">
<td>Microsoft Windows 2000</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Identifier</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=130719"><strong>MS08-067</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128125"><strong>MS08-060</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128060"><strong>MS08-058</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=125709"><strong>MS08-066</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=121738"><strong>MS08-061</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=120829"><strong>MS08-062</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=127994"><strong>MS08-063</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128103"><strong>MS08-064</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128102"><strong>MS08-065</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Maximum Severity Rating</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Microsoft Windows 2000 Service Pack 4</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=E22EB3AE-1295-4FE2-9775-6F43C5C2AED3">Microsoft Windows 2000 Service Pack 4</a><br />
(Critical)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=8ed7bb9a-4b26-49d7-8c14-60226d2bc20d">Active Directory on Microsoft Windows 2000 Server Service Pack 4</a><br />
(Critical)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=257C0478-56DD-42EB-A90E-607D01613DB7">Microsoft Internet Explorer 5.01 Service Pack 4</a><br />
(Critical)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=02390258-08E9-4B75-960D-BE081B749558">Microsoft Internet Explorer 6 Service Pack 1</a><br />
(Critical)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=3a6165a6-d7e7-4526-9291-290caf0639b4">Microsoft Windows 2000 Service Pack 4</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=8163d1f6-feb5-4f39-8134-3ed42326b822">Microsoft Windows 2000 Service Pack 4</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=9ED29C3A-0682-4586-BBC2-A73DEAA18E4C">Microsoft Windows 2000 Service Pack 4</a><br />
(Important)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=899e2728-2433-4ccb-a195-05b5d65e5469">Microsoft Windows 2000 Service Pack 4</a><br />
(Important)</td>
</tr>
<tr class="subHeader">
<td>Windows XP</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Identifier</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=130719"><strong>MS08-067</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128125"><strong>MS08-060</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=128060"><strong>MS08-058</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=125709"><strong>MS08-066</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=121738"><strong>MS08-061</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=120829"><strong>MS08-062</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=127994"><strong>MS08-063</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128103"><strong>MS08-064</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128102"><strong>MS08-065</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Maximum Severity Rating</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Windows XP Service Pack 2 and Windows XP Service Pack 3</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=0D5F9B6E-9265-44B9-A376-2067B73D6A03">Windows XP Service Pack 2 and Windows XP Service Pack 3</a><br />
(Critical)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=A7F0F47B-B1EE-4516-9FBF-BF8E579963D0">Microsoft Internet Explorer 6</a><br />
(Critical)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=4E73DE2B-05E6-4901-9BAC-46D8F469E635">Windows Internet Explorer 7</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=b16d9dac-c430-4dd8-a1e5-9a614801f1d9">Windows XP Service Pack 2 and Windows XP Service Pack 3</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=7718bf14-c26c-43f3-be67-4c79ab5b2607">Windows XP Service Pack 2 and Windows XP Service Pack 3</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=e7ef571f-c9e8-4e14-95a3-3eeaec55b784">Windows XP Service Pack 2 and Windows XP Service Pack 3</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=2F7E5981-6EEF-4F08-86C0-C6A7607EA5D0">Windows XP Service Pack 2 and Windows XP Service Pack 3</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=25997b73-a640-49c1-b19e-768a18bbe22c">Windows XP Service Pack 2 and Windows XP Service Pack 3</a><br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell">Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=4C16A372-7BF8-4571-B982-DAC6B2992B25">Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2</a><br />
(Critical)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=234C05FB-988B-4E02-AAB6-BB23E447DF3D">Microsoft Internet Explorer 6</a><br />
(Critical)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=CCF7A3E3-EC30-4B95-9A86-00032301513C">Windows Internet Explorer 7</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=5b607efc-c6fb-4079-8478-e4f3262386d3">Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=b06d3a02-b6e4-4d40-913a-3759a31f20f3">Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=3ae4b913-bff0-4974-b198-828ca10d2a87">Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=4E1675EB-6B06-48E9-9765-23A2C7737BDC">Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=50fae854-0bde-46f8-9444-b9e0d9bfecad">Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2</a><br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="subHeader">
<td>Windows Server 2003</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Identifier</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=130719"><strong>MS08-067</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128125"><strong>MS08-060</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=128060"><strong>MS08-058</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=125709"><strong>MS08-066</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=121738"><strong>MS08-061</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=120829"><strong>MS08-062</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=127994"><strong>MS08-063</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128103"><strong>MS08-064</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128102"><strong>MS08-065</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Maximum Severity Rating</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=F26D395D-2459-4E40-8C92-3DE1C52C390D">Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2</a><br />
(Critical)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=AE8D22D5-20AA-471D-A423-F54C9D75FEBE">Microsoft Internet Explorer 6</a><br />
(Moderate)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=FEAF2ADF-7892-4DBF-A147-DB4D5DBE52F3">Windows Internet Explorer 7</a><br />
(Low)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ee88ff2d-1b12-4f4c-a081-9f27a6fba074">Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=6e696762-d652-4a8f-ab8f-622f9746c320">Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=437a9b68-6a0c-48c8-9348-0d6fda48aa21">Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=DBBEBB3F-F1C7-402C-BD16-6F88DA0D042C">Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=e8ef3d5f-dd8e-4945-92cd-9d3e30b16667">Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2</a><br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell">Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=C04D2AFB-F9D0-4E42-9E1F-4B944A2DE400">Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2</a><br />
(Critical)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=07FC88C4-2571-4A4D-B573-AE576798AB4C">Microsoft Internet Explorer 6</a><br />
(Moderate)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=319DBA34-07CA-47F9-A1E9-20DF2DF7966B">Windows Internet Explorer 7</a><br />
(Low)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ab4d94d3-458c-4946-ab7f-03a279629d25">Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=57ca28ea-e5e1-4191-a3d6-84aa90a3d668">Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=d3df6508-a568-449d-ac97-fbf3f97b98ef">Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=989AC6F1-515C-467D-A200-2AABE66D9319">Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=c2e754f9-086a-494c-bc19-5feed7df8b65">Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2</a><br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=AB590756-F11F-43C9-9DCC-A85A43077ACF">Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems</a><br />
(Critical)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=B68937AF-F04A-4D1E-9D7F-EC92AF5194DE">Microsoft Internet Explorer 6</a><br />
(Moderate)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=47381D91-4A14-4A09-96B3-3345155DF52D">Windows Internet Explorer 7</a><br />
(Low)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=63234f85-6e5d-4ef6-b7cf-d1d2c78a5517">Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=1e6c3f81-85bb-48e6-a5af-635a7e540c93">Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=748f54f1-40b9-407c-9819-909061b53743">Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=91589CFB-15BA-4DD2-9E3B-107899FBCBA6">Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=5a3832ec-3f8f-42c1-a603-b1330d527547">Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems</a><br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="subHeader">
<td>Windows Vista</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Identifier</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=130719"><strong>MS08-067</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128125"><strong>MS08-060</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=128060"><strong>MS08-058</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=125709"><strong>MS08-066</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=121738"><strong>MS08-061</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=120829"><strong>MS08-062</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=127994"><strong>MS08-063</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128103"><strong>MS08-064</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128102"><strong>MS08-065</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Maximum Severity Rating</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Windows Vista and Windows Vista Service Pack 1</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=18FDFF67-C723-42BD-AC5C-CAC7D8713B21">Windows Vista and Windows Vista Service Pack 1</a><br />
(Important)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=4756E04B-6E1C-4D78-A3C0-17F6B4B97975">Windows Internet Explorer 7</a><br />
(Important)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=3483b400-cedc-441f-ba8e-594e3df89190">Windows Vista and Windows Vista Service Pack 1</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=9B5995DF-A3B8-4E81-B118-9BB057E19884">Windows Vista and Windows Vista Service Pack 1</a><br />
(No severity rating)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=72DD6015-25D1-45F4-A769-88AC43074B44">Windows Vista and Windows Vista Service Pack 1</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=b4212db5-093e-497d-b999-2e3780f9f7c2">Windows Vista and Windows Vista Service Pack 1</a><br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell">Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=A976999D-264F-4E6A-9BD6-3AD9D214A4BD">Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1</a><br />
(Important)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=BD19C72B-4F83-47AB-93BE-D2C286E732C4">Windows Internet Explorer 7</a><br />
(Important)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=905ab030-14a5-4a3d-aa11-e8f957f6a1ea">Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=4A0FCF4B-EB8E-456A-B934-400AE18248EE">Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1</a><br />
(No severity rating)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=F793AF16-5464-4DB1-A42B-1C5F17C538ED">Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=c20808cb-c30a-4b53-91e5-810eb6b4b2e3">Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1</a><br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="subHeader">
<td>Windows Server 2008</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Identifier</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=130719"><strong>MS08-067</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128125"><strong>MS08-060</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=128060"><strong>MS08-058</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=125709"><strong>MS08-066</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=121738"><strong>MS08-061</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=120829"><strong>MS08-062</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=127994"><strong>MS08-063</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128103"><strong>MS08-064</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128102"><strong>MS08-065</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Maximum Severity Rating</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Important</strong></a></p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Windows Server 2008 for 32-bit Systems</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=25C17B07-1EFE-43D7-9B01-3DFDF1CE0BD7">Windows Server 2008 for 32-bit Systems</a>*<br />
(Important)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=EC73F416-2204-42D6-8932-C96578AC819F">Windows Internet Explorer 7</a>**<br />
(Low)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=8b97114a-71aa-47a2-b9e7-f4e158c18c80">Windows Server 2008 for 32-bit Systems</a>*<br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=3d6290d8-1745-4bc0-9ca9-eeb1ad0be4a5">Windows Server 2008 for 32-bit Systems</a>*<br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=CF6744E6-B54C-40F6-A78D-7BA9453133C0">Windows Server 2008 for 32-bit Systems</a>*<br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=ec9eeb82-0497-4c55-94bb-9a47cb3521b4">Windows Server 2008 for 32-bit Systems</a>*<br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell">Windows Server 2008 for x64-based Systems</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=7B12018E-0CC1-4136-A68C-BE4E1633C8DF">Windows Server 2008 for x64-based Systems</a>*<br />
(Important)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=BAACD1C2-9764-4FEA-BD4D-C49791974FEF">Windows Internet Explorer 7</a>**<br />
(Low)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=6e641db2-90c8-458f-9795-3e46b70a5203">Windows Server 2008 for x64-based Systems</a>*<br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=a33c833c-d5c5-4e37-8f89-7b9079f92e59">Windows Server 2008 for x64-based Systems</a>*<br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=223236E8-7B19-4B47-8A90-BFC35EB9318A">Windows Server 2008 for x64-based Systems</a>*<br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=0bc178b8-f8ae-4f41-8f88-fb6a75be1bca">Windows Server 2008 for x64-based Systems</a>*<br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Windows Server 2008 for Itanium-based Systems</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=2BCF89EF-6446-406C-9C53-222E0F0BAF7A">Windows Server 2008 for Itanium-based Systems</a><br />
(Important)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=250A45DD-7EAE-4440-BD10-02A703940976">Windows Internet Explorer 7</a><br />
(Low)</td>
<td>
<p class="lastInCell">Not applicable</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=b6546e1c-bf7b-4354-8574-6c16fa707de0">Windows Server 2008 for Itanium-based Systems</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=31783e88-76e2-4bc6-b4ae-308443c6d223">Windows Server 2008 for Itanium-based Systems</a><br />
(No severity rating)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=077B697C-04A0-45BD-B08C-331D5C30CB47">Windows Server 2008 for Itanium-based Systems</a><br />
(Important)</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=0af72663-4945-4916-8c55-090ba4d82793">Windows Server 2008 for Itanium-based Systems</a><br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
</tbody>
</table>
<p><strong>*Windows Server 2008 server core installation affected.</strong> For supported editions of Windows Server 2008, this update applies, with the same severity rating, whether or not Windows Server 2008 was installed using the Server Core installation option. For more information on this installation option, see <a href="http://msdn.microsoft.com/en-us/library/ms723891%28VS.85%29.aspx">Server Core</a>. Note that the Server Core installation option does not apply to certain editions of Windows Server 2008; see <a href="http://www.microsoft.com/windowsserver2008/en/us/compare-core-installation.aspx">Compare Server Core Installation Options</a>.</p>
<p><strong>**Windows Server 2008 server core installation not affected.</strong> The vulnerabilities addressed by these updates do not affect supported editions of Windows Server 2008 if Windows Server 2008 was installed using the Server Core installation option. For more information on this installation option, see <a href="http://msdn.microsoft.com/en-us/library/ms723891%28VS.85%29.aspx">Server Core</a>. Note that the Server Core installation option does not apply to certain editions of Windows Server 2008; see <a href="http://www.microsoft.com/windowsserver2008/en/us/compare-core-installation.aspx">Compare Server Core Installation Options</a>.</div>
<div class="secTop"><a href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EKSAE"><img src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/arrow_px_up.gif" border="0" alt="Top of section" width="7" height="9" /></a><a class="topOfPage" href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EKSAE">Top of section</a></div>
</div>
<p><a name="EE5AG"></a></p>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding: 2px 6px 0px 0px;"><script type="text/javascript"><!--
sID='8l2-EE5AG';writePM(sID)
// --></script><a href="javascript:Toggle('s8l2-EE5AG')"><img id="is8l2-EE5AG" src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/plus.gif" border="0" alt="" width="9" height="9" /></a></td>
<td class="secLabel"><script type="text/javascript"><!--
startA('s'+sID)
// --></script></p>
<h4><a style="text-decoration: none;" href="javascript:Toggle('s8l2-EE5AG')">Microsoft Office Suites and Software</a></h4>
<p><script type="text/javascript"><!--
endA()
// --></script></td>
</tr>
</tbody>
</table>
<div id="s8l2-EE5AG" style="display: none;"><script type="text/javascript"><!--
chkHide('s'+sID);
// --></script></p>
<div class="expandoIndent">
<table id="EI5AG" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="81%">
<thead></thead>
<tbody>
<tr class="subHeader">
<td>Microsoft Office Suites, Systems, and Components</td>
<td></td>
<td></td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Identifier</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=124653"><strong>MS08-057</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128145"><strong>MS08-056</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Maximum Severity Rating</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Moderate</strong></a></p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Microsoft Office 2000 Service Pack 3</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=1b2740e0-ecdd-48ca-84e0-eb187c31eb16">Excel 2000 Service Pack 3</a><br />
(KB955461)<br />
(Critical)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell">Microsoft Office XP Service  Pack 3</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=27cedef1-c47c-472c-a343-cd9b4ebc2bba">Excel 2002 Service Pack 3</a><br />
(KB955464)<br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=b1aee2d5-bfa0-40e3-91b6-98bf65524e8c">Microsoft Office XP Service Pack 3</a><br />
(KB956464)<br />
(Moderate)</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Microsoft Office 2003 Service Pack 2 and Microsoft Office 2003 Service Pack 3</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=4df27e8a-d803-483b-a700-0177d71bf368">Excel 2003 Service Pack 2</a><br />
(KB955466)<br />
(Important)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=4df27e8a-d803-483b-a700-0177d71bf368">Excel 2003 Service Pack 3</a><br />
(KB955466)<br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell">2007 Microsoft Office System and 2007 Microsoft Office System Service Pack 1</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=2765bbc0-ea2e-4b6e-822c-222ee8e5021f">Excel 2007</a><br />
(KB955470)<br />
(Important)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=2765bbc0-ea2e-4b6e-822c-222ee8e5021f">Excel 2007 Service Pack 1</a><br />
(KB955470)<br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="subHeader">
<td>Microsoft Office for Mac</td>
<td></td>
<td></td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Identifier</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=124653"><strong>MS08-057</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128145"><strong>MS08-056</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Maximum Severity Rating</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Moderate</strong></a></p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Microsoft Office 2004 for Mac</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=BA4FA21A-7E01-4EF8-9B9F-9D51D00EF094">Microsoft Office 2004 for Mac</a><br />
(KB958312)<br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell">Microsoft Office 2008 for Mac</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=E70C5AE0-2858-46DE-81F8-DCD1786656B7">Microsoft Office 2008 for Mac</a><br />
(KB958267)<br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Open XML File Format Converter for Mac</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=2A8D9A3B-B8A4-43B6-82A6-A2E7D16AE11D">Open XML File Format Converter for Mac</a><br />
(KB958304)<br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="subHeader">
<td>Other Office Software</td>
<td></td>
<td></td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Identifier</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkID=124653"><strong>MS08-057</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=128145"><strong>MS08-056</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Maximum Severity Rating</strong></p>
</td>
<td>
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Moderate</strong></a></p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Microsoft Office Excel Viewer</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=9769ce08-5207-4c63-b7b9-536266ad6b2b">Microsoft Office Excel Viewer 2003</a><br />
(KB955468)<br />
(Important)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=9769ce08-5207-4c63-b7b9-536266ad6b2b">Microsoft Office Excel Viewer 2003 Service Pack 3</a><br />
(KB955468)<br />
(Important)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=83c88444-75b8-44d1-b280-3671394ade45">Microsoft Office Excel Viewer</a><br />
(KB955935)<br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell">Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=9a7be004-5903-4101-90c5-c0d5f8722af9">Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats</a><br />
(KB955936)<br />
(Important)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=9a7be004-5903-4101-90c5-c0d5f8722af9">Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1</a><br />
(KB955936)<br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Microsoft Office SharePoint Server 2007</p>
</td>
<td>
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=5c29e646-504c-4455-9d35-9a1bed6d7535">Microsoft Office SharePoint Server 2007</a>*<br />
(KB955937)<br />
(Important)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=5c29e646-504c-4455-9d35-9a1bed6d7535">Microsoft Office SharePoint Server 2007 Service Pack 1</a>*<br />
(KB955937)<br />
(Important)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=3c21c405-2c9e-45d0-be4d-8ccd093af31f">Microsoft Office SharePoint Server 2007 x64 Edition</a>*<br />
(KB955937)<br />
(Important)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=3c21c405-2c9e-45d0-be4d-8ccd093af31f">Microsoft Office SharePoint Server 2007 x64 Edition Service Pack 1</a>*<br />
(KB955937)<br />
(Important)</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell">Not applicable</p>
</td>
</tr>
</tbody>
</table>
<p>*This update applies to servers that have Excel Services installed, such as the default configuration of Microsoft Office SharePoint Server 2007 Enterprise and Microsoft Office SharePoint Server 2007 For Internet Sites. Microsoft Office SharePoint Server 2007 Standard does not include Excel Services.</p></div>
<div class="secTop"><a href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EE5AG"><img src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/arrow_px_up.gif" border="0" alt="Top of section" width="7" height="9" /></a><a class="topOfPage" href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EE5AG">Top of section</a></div>
</div>
<p><a name="EMJBG"></a></p>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding: 2px 6px 0px 0px;"><script type="text/javascript"><!--
sID='8l2-EMJBG';writePM(sID)
// --></script><a href="javascript:Toggle('s8l2-EMJBG')"><img id="is8l2-EMJBG" src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/plus.gif" border="0" alt="" width="9" height="9" /></a></td>
<td class="secLabel"><script type="text/javascript"><!--
startA('s'+sID)
// --></script></p>
<h4><a style="text-decoration: none;" href="javascript:Toggle('s8l2-EMJBG')">Microsoft Server Software</a></h4>
<p><script type="text/javascript"><!--
endA()
// --></script></td>
</tr>
</tbody>
</table>
<div id="s8l2-EMJBG" style="display: none;"><script type="text/javascript"><!--
chkHide('s'+sID);
// --></script></p>
<div class="expandoIndent">
<table id="EQJBG" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="58%">
<thead></thead>
<tbody>
<tr class="subHeader">
<td>Microsoft Host Integration Server</td>
<td></td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Identifier</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=125712"><strong>MS08-059</strong></a></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell"><strong>Bulletin Maximum Severity Rating</strong></p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><strong>Critical</strong></a></p>
</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Microsoft Host Integration Server 2000</p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=11CCA58B-59A4-4E93-9EB1-19B07C290A10">Microsoft Host Integration Server 2000 Service Pack 2 (Server)</a><br />
(Critical)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=41B49291-1231-4E23-AEF7-818207453D56">Microsoft Host Integration Server 2000 Administrator Client</a><br />
(Critical)</td>
</tr>
<tr class="evenRecord" valign="top">
<td>
<p class="lastInCell">Microsoft Host Integration Server 2004</p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=9CA255ED-9334-4848-AF94-49EF3078CDC0">Microsoft Host Integration Server 2004 (Server)</a><br />
(Critical)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=ECA756A1-CA56-4481-B23C-53C159A4E08C">Microsoft Host Integration Server 2004 Service Pack 1 (Server)</a><br />
(Critical)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=92CB54E7-F4FF-40A4-99CB-6257C4D8D4CD">Microsoft Host Integration Server 2004 (Client)</a><br />
(Critical)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=D776515C-09AA-4A04-876D-606BFC26A006">Microsoft Host Integration Server 2004 Service Pack 1 (Client)</a><br />
(Critical)</td>
</tr>
<tr class="record" valign="top">
<td>
<p class="lastInCell">Microsoft Host Integration Server 2006</p>
</td>
<td style="border-right: 1px solid #cccccc;">
<p class="lastInCell"><a href="http://www.microsoft.com/downloads/details.aspx?familyid=1AE79DA3-EC17-4D4B-8011-D777A237AC93">Microsoft Host Integration Server 2006 for 32-bit Systems</a><br />
(Critical)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=05DA4540-4976-458A-A612-7385D78695A2">Microsoft Host Integration Server 2006 for x64-based Systems</a><br />
(Critical)</td>
</tr>
</tbody>
</table>
</div>
<div class="secTop"><a href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EMJBG"><img src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/arrow_px_up.gif" border="0" alt="Top of section" width="7" height="9" /></a><a class="topOfPage" href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#EMJBG">Top of section</a></div>
</div>
</div>
<div class="secTop"><a href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#E6RAE"><img src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/arrow_px_up.gif" border="0" alt="Top of section" width="7" height="9" /></a><a class="topOfPage" href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx#E6RAE">Top of section</a></div>
</div>
<p><a name="EUMBG"></a></p>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding: 6px 6px 0px 0px;"><script type="text/javascript"><!--
sID='8l1-EUMBG';writePM(sID)
// --></script><a href="javascript:Toggle('s8l1-EUMBG')"><img id="is8l1-EUMBG" src="http://www.microsoft.com/library/gallery/templates/MNP2.Common/images/plus.gif" border="0" alt="" width="9" height="9" /></a></td>
<td class="secLabel"><script type="text/javascript"><!--
startA('s'+sID)
// --></script></p>
<h3><a style="text-decoration: none;" href="javascript:Toggle('s8l1-EUMBG')">Detection and Deployment Tools and Guidance</a></h3>
<p><script type="text/javascript"><!--
endA()
// --></script></td>
</tr>
</tbody>
</table>
<div id="s8l1-EUMBG" style="display: none;"><script type="text/javascript"><!--
chkHide('s'+sID);
// --></script></p>
<div class="expandoIndent">
<p><strong>Security Central</strong></p>
<p>Manage the software and security updates you need to deploy to the servers, desktop, and mobile computers in your organization. For more information see the <a href="http://go.microsoft.com/fwlink/?LinkId=69903">TechNet Update Management Center</a>. The <a href="http://go.microsoft.com/fwlink/?LinkId=21171">TechNet Security Center</a> provides additional information about security in Microsoft products. Consumers can visit <a href="http://go.microsoft.com/fwlink/?LinkId=85102">Security At Home</a>, where this information is also available by clicking “Latest Security Updates”.</p>
<p>Security updates are available from <a href="http://go.microsoft.com/fwlink/?LinkID=40747">Microsoft Update</a>, <a href="http://go.microsoft.com/fwlink/?LinkId=21130">Windows Update</a>, and <a href="http://go.microsoft.com/fwlink/?LinkId=21135">Office Update</a>. Security updates are also available at the <a href="http://go.microsoft.com/fwlink/?LinkId=21129">Microsoft Download Center</a>. You can find them most easily by doing a keyword search for &#8220;security update&#8221;.</p>
<p>Finally, security updates can be downloaded from the <a href="http://go.microsoft.com/fwlink/?LinkId=96155">Microsoft Update Catalog</a>. The Microsoft Update Catalog provides a searchable catalog of content made available through Windows Update and Microsoft Update, including security updates, drivers and service packs. By searching using the security bulletin number (such as, “MS07-036”), you can add all of the applicable updates to your basket (including different languages for an update), and download to the folder of your choosing. For more information about the Microsoft Update Catalog, see the <a href="http://go.microsoft.com/fwlink/?LinkId=97900">Microsoft Update Catalog FAQ</a>.</p>
<p><strong>Detection and Deployment Guidance</strong></p>
<p>Microsoft has provided detection and deployment guidance for this month’s security updates. This guidance will also help IT professionals understand how they can use various tools to help deploy the security update, such as Windows Update, Microsoft Update, Office Update, the Microsoft Baseline Security Analyzer (MBSA), the Office Detection Tool, Microsoft Systems Management Server (SMS), and the Extended Security Update Inventory Tool (ESUIT). For more information, see <a href="http://support.microsoft.com/kb/910723">Microsoft Knowledge Base Article 910723</a>.</p>
<p><strong>Microsoft Baseline 